a local text forensics lab — paste anything, trust nothing, transmit nothing
◉ offline-ready · 0 bytes leave this page
The whole lab on one text. Every single-input instrument runs at once — hidden characters, secrets, prose, manipulation pressure, redaction preview — and you get one composed verdict plus a downloadable dossier. For anything you're about to forward, sign, publish or feed to an agent.
Ctrl+Enter runs · Ctrl+K commands
What your eyes can't see. Zero-width characters, direction overrides, homoglyphs and metadata tags smuggle secret messages, rig searches, spoof brands and plant prompt-injections. The census reads every code point, decodes hidden payloads, and the ghost view makes the invisible visible.
secret to hide:(letters and spaces only — it will be invisible)
Before you paste that into a chatbot / repo / ticket. Credentials and personal data found with real checksum math — Luhn for cards, mod-97 for IBANs — so a fake card doesn't cry wolf and a real one can't hide. JWTs get decoded, not just matched.
Was it copied? Winnowing fingerprinting — the algorithm behind production plagiarism systems — matches survive reformatting and small edits. Shared passages are quoted with offsets and coverage percentages.
Who wrote this? Every writer has a statistical fingerprint: how often they reach for “the” vs “a”, semicolons vs dashes, long sentences vs short. The comparison reads habits, never meaning. Add 2–5 texts.
The edit your text is asking for. Classic readability grades (Flesch, Fog, SMOG, Dale-Chall) plus the things editors actually flag: filler, clichés, hedges, passive voice, nominalizations, echoes, monotone rhythm. Every finding quotes its evidence.
Make it safe to paste. Secrets become typed placeholders — [REDACTED AWS KEY], [REDACTED CARD NUMBER] — in a copyable block. Emails, phones and IPs stay by default (often legitimate); flip the switch to strip those too. The output is built in this tab and never sent anywhere.
What exactly changed — and was anything smuggled in? A word-level diff of two versions; every edit that introduces invisible characters (a zero-width tweak, a bidi override) is flagged. The classic move: a contract where “100” became “1000” with a direction override hiding it.
Manipulation & prompt-injection heuristics. Pattern-level pressure signs: urgency and authority plays, credential phishing hooks, payment tricks, instruction overrides, forged system tags and messages addressed to AI agents. A smoke detector, not a verdict — honest about false positives.
this link carries text in its fragment (never sent to any server)